Bug #67363 [Com]: Unserialize corrupts data

From: Date: Sat, 07 Jan 2017 19:57:29 +0000
Subject: Bug #67363 [Com]: Unserialize corrupts data
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206360@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67363&edit=1 ID: 67363 Comment by: jh1711 at xmail dot net Reported by: mg at artigo dot pl Summary: Unserialize corrupts data Status: Open Type: Bug Package: Variables related Operating System: Irrelavant PHP Version: Irrelevant Block user comment: N Private report: N New Comment: @laszlokorte, there's a mistake in your gist. Definition::unserialize should pass $data to unserialize, or use $value as a parameter. Unserializing an uninitialized variable causes the false values, and not unserializing the parameter messes up the references. See https://3v4l.org/vioIT . @nikic, imho the cause of bug #66085 is serializing additional data during serialization. Of course this can result in similar behaviour. See https://3v4l.org/9hVS2 . Previous Comments: ------------------------------------------------------------------------ [2017-01-07 18:36:19] php at laszlokorte dot de @nikic Thanks, indeed the problem of the gist I posted is solved by php7. But in my real application I now get many "Notice: unserialize(): Error at offset 1026 of 1348 bytes" errors. ------------------------------------------------------------------------ [2017-01-07 17:58:57] nikic@php.net @laszlokorte: That is most likely bug #66085, which is fixed in PHP 7.0 (but not 5.6). ------------------------------------------------------------------------ [2017-01-07 17:45:03] php at laszlokorte dot de Not sure if this is the correct issue but I came across some problem with serialize/unserialize. (php-5.6.14) I have created a gist to reproduce it: https://gist.github.com/laszlokorte/3948f40873346cc1fd9b8c11ab06ae04 The problem is that if an object contains a another object as child in multiple places that child does not get (un)serialized correctly. Not just that the identity of the multiple occurrences is not preserved but the object is not unserialized correctly at all. It's easier to understand by looking at gist. ------------------------------------------------------------------------ [2017-01-01 13:36:14] mg at artigo dot pl Maybe I should add that the issue was present for sure without opcache and it was not the case of shared memory, because we could repeat it any time, on any day with the same result and same corruption. ------------------------------------------------------------------------ [2017-01-01 13:31:19] mg at artigo dot pl Dear Nikita, I wish you a Happy New Year with lots of happiness and joy. It has been so long since the issue was reported, that we managed to implement some workarounds in the meantime and we do not encounter it anymore. That said, if I encounter it again, I will open another issue, ok? Thanks, Marcin ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=67363 -- Edit this bug report at https://bugs.php.net/bug.php?id=67363&edit=1

« previous php.bugs (#206360) next »